Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

hazikubu.dll (rundll32.exe) malware


  • This topic is locked This topic is locked
28 replies to this topic

#1 Sashacat

Sashacat

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 15 February 2010 - 04:23 PM

Posting DDS log per boopme's instructions:
http://www.bleepingcomputer.com/forums/ind...03&t=293472

My original post was because I have a rundll32.exe running in Task Mngr.
Process Explorer showed the command line for the rundll32.exe as:
C:\WINDOWS\system32\rundll32.exe "C:\WINDOWS\system32\hazikubu.dll",d

I have a hazikubu entry in the registry as follows:
HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\
000 (Name), REG_SZ (Type), hazikubu*.*(Data)


I followed boopme's instructions.......I've scanned with SUPERAnti-Spyware, Malwarebytes' Antimalware, AVG Free, and ESET Online Scanner, posted the logs showing infected items, fixed items, etc., and I posted the logs where all scans now run "clean" (no infections). boopme's latest instructions were to use ERUNT and DDS, which I did.
I have NOT made any changes to the registry, because my experience editing the registry is limited.

The rundll32.exe still runs in Task Mngr.

I noticed in the DDS log, a mention of Yahoo Toolbar. I don't have Yahoo Toolbar installed. Is that the result of Yahoo Toolbar having been installed at a previous time?
Also, the DDS log mentions:LSA: Notification Packages = scecli bahezido.dll
That bahezido.dll entry concerns me......
Also, I briefly had the Online Armor (free) firewall program, but uninstalled it, as it used up too much resources, made this old laptop run so slow it was not usable. I notice there are OA entries as well.

Without further ado, here is the DDS log, (copied/pasted), and am attaching the Attach.txt file.
I will await your response, for advice on how to fix.
Many thanks :
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -


DDS (Ver_09-12-01.01) - NTFSx86
Run by Lisa Hill at 15:38:30.98 on Mon 02/15/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.191.13 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Lisa Hill\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.wftv.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
uPolicies-explorer: NoActiveDesktop = 01000000
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
IE: &Search
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522}
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon -
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter -
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File
LSA: Notification Packages = scecli bahezido.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lisahi~1\applic~1\mozilla\firefox\profiles\gct4q43z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-4-25 333192]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-1-9 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-4-25 360584]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2010-2-1 200784]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2010-2-1 24656]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2010-2-1 29776]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-1-20 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-20 285392]
S2 mrtRate;mrtRate; [x]
S3 apusbsnt;Sierra Wireless USB Modem Device Driver;c:\windows\system32\drivers\apusbsnt.sys --> c:\windows\system32\drivers\apusbsnt.sys [?]
S3 ECnvtBox;Embroidery Conversion Box Plus;c:\windows\system32\drivers\ECnvtBox.sys [2005-1-8 37818]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2006-9-14 92160]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S4 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2010-2-1 1858144]
S4 OAcat;Online Armor Helper Service;"c:\program files\tall emu\online armor\oacat.exe" --> c:\program files\tall emu\online armor\OAcat.exe [?]

=============== Created Last 30 ================

2010-02-11 19:29:07 0 d-----w- c:\windows\system32\Adobe
2010-02-10 13:31:57 12568 ----a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2010-02-09 20:04:13 0 d-----w- c:\program files\ESET
2010-02-05 18:23:49 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 14:37:46 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-01 14:37:45 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-01 14:37:25 200784 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-01 14:33:59 0 d-----w- c:\program files\a-squared Free
2010-02-01 03:49:03 0 d-----w- c:\docume~1\lisahi~1\applic~1\Malwarebytes
2010-02-01 03:28:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 03:28:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-01 03:28:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-31 22:54:23 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:49:39 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-31 22:49:38 0 d-----w- c:\docume~1\lisahi~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:46:54 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-31 20:56:32 1744 ---ha-w- c:\windows\system32\dobijuzi
2010-01-31 20:35:10 0 d-----w- c:\docume~1\lisahi~1\applic~1\WinPatrol
2010-01-31 20:34:11 0 d-----w- c:\program files\BillP Studios
2010-01-28 15:58:12 0 d-----w- c:\program files\ShowMyPC
2010-01-28 15:41:16 0 d-----w- c:\documents and settings\lisa hill\Tracing
2010-01-28 15:27:05 0 d-----w- c:\program files\Microsoft
2010-01-28 15:26:18 0 d-----w- c:\program files\Windows Live SkyDrive
2010-01-28 15:05:16 0 d-----w- c:\program files\common files\Windows Live
2010-01-27 12:57:57 0 d-----w- c:\program files\K9
2010-01-24 18:28:57 0 d-----w- c:\windows\SxsCaPendDel
2010-01-24 15:26:05 0 d-----w- c:\docume~1\lisahi~1\applic~1\AVG9
2010-01-23 14:03:57 0 d-----w- c:\program files\common files\HP
2010-01-23 14:02:06 0 d-----w- c:\program files\Winamp Detect
2010-01-23 05:25:22 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-01-23 05:16:38 970752 ----a-w- c:\windows\system32\hpotiop5.dll
2010-01-23 05:16:37 364544 ----a-w- c:\windows\system32\hppldcoi.dll
2010-01-23 05:16:37 303104 ----a-w- c:\windows\system32\hpovst12.dll
2010-01-23 05:16:36 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-01-23 05:16:35 729088 ----a-w- c:\windows\system32\hpowiax5.dll
2010-01-23 05:10:17 166269 ----a-w- c:\windows\hpoins21.dat
2010-01-23 05:10:16 7262 ------w- c:\windows\hpomdl21.dat
2010-01-22 23:31:20 7262 ------w- c:\windows\hpomdl21.dat.temp
2010-01-22 23:31:20 164690 ------w- c:\windows\hpoins21.dat.temp
2010-01-21 18:44:18 3472 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-21 18:32:53 0 d-----w- c:\windows\Logs
2010-01-21 00:56:44 0 d--h--w- C:\$AVG
2010-01-17 23:53:43 0 d-----w- c:\program files\Walmart MP3 Music Downloads
2010-01-17 13:39:00 0 d-sh--w- c:\docume~1\alluse~1\applic~1\System Restore
2010-01-16 21:59:04 7680 ----a-w- c:\windows\system32\ff_acm.acm
2010-01-16 21:59:03 0 d-----w- c:\program files\ffdshow
2010-01-16 21:57:40 0 d-----w- c:\program files\PlayFLV
2010-01-16 21:44:47 547 ----a-w- c:\windows\system32\ff_vfw.dll.manifest
2010-01-16 21:44:44 6144 ----a-w- c:\windows\system32\ff_vfw.dll

==================== Find3M ====================

2010-01-30 23:24:07 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-27 19:13:56 30868 ----a-w- c:\windows\fonts\IllegalEdding.ttf
2010-01-27 19:13:08 100572 ----a-w- c:\windows\fonts\Degrassi.ttf
2010-01-27 19:12:36 53352 ----a-w- c:\windows\fonts\Searfont.ttf
2010-01-27 19:11:42 68352 ----a-w- c:\windows\fonts\Rufa.ttf
2010-01-21 00:48:40 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-21 00:48:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-21 00:48:39 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-19 18:38:28 66536 ----a-w- c:\windows\fonts\PressWriter_Symbols.ttf
2010-01-14 16:35:44 19573 ----a-w- c:\windows\hpqins13.dat
2010-01-13 08:31:43 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-01-13 08:31:21 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-13 03:36:09 69 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences2.dat
2010-01-13 03:36:09 39 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences.dat
2010-01-05 21:24:16 21704 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-01-05 21:24:14 18632 ----a-w- c:\windows\system32\dopdfmi7.dll
2009-11-21 16:36:13 470528 ----a-w- c:\windows\system32\dllcache\aclayers.dll

============= FINISH: 15:40:50.46 ===============

Attached Files


If we don't change the direction we are going,
We are likely to end up where we are headed.

BC AdBot (Login to Remove)

 


#2 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:33 AM

Posted 17 February 2010 - 06:56 PM

HI-

Yup, you've got some malware. Before we fix it, I need a deeper scan. Please do the following:
Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#3 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 17 February 2010 - 08:51 PM

etavares,
The first thing I would like to say is "thank you". I am very grateful for your help smile.gif

I followed your instructions exactly, and am pasting the gmer log below:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-17 20:30:38
Windows 5.1.2600 Service Pack 2
Running: k9y658lk.exe; Driver: C:\DOCUME~1\LISAHI~1\LOCALS~1\Temp\fwtdapoc.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwAllocateVirtualMemory [0xF410EE60]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwAssignProcessToJobObject [0xF410F5C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwConnectPort [0xF410D610]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreateFile [0xF411C0D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreateKey [0xF411A430]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreatePort [0xF410D2C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreateProcess [0xF410A580]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreateProcessEx [0xF410A960]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreateSection [0xF410A060]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwCreateThread [0xF410BA40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwDebugActiveProcess [0xF410C5A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwDeleteFile [0xF411CB50]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwDeleteKey [0xF411A9E0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwDeleteValueKey [0xF411B330]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwDuplicateObject [0xF410CFE0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwEnumerateKey [0xF411C070]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwEnumerateValueKey [0xF411C0A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwLoadDriver [0xF410E5D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwLoadKey [0xF411B780]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwOpenFile [0xF411C760]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwOpenKey [0xF411AC20]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwOpenProcess [0xF410B450]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwOpenSection [0xF410A300]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwOpenThread [0xF410BF00]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwProtectVirtualMemory [0xF410F250]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwQueryDirectoryFile [0xF410EA10]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwQueryKey [0xF411C010]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwQueryValueKey [0xF411C040]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwQueueApcThread [0xF410F740]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwReplaceKey [0xF411BB20]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwRequestWaitReplyPort [0xF410E180]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwRestoreKey [0xF411BD80]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwResumeThread [0xF410CC90]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSaveKey [0xF411BFF0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSecureConnectPort [0xF410D9D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSetContextThread [0xF410C3C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSetSystemInformation [0xF410C720]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSetValueKey [0xF411AC40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwShutdownSystem [0xF410E4D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSuspendProcess [0xF410CE40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSuspendThread [0xF410CAC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwSystemDebugControl [0xF410C900]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwTerminateProcess [0xF410B800]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwTerminateThread [0xF410C1A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwUnloadDriver [0xF410E7F0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys (OA Helper Driver/Tall Emu) ZwWriteVirtualMemory [0xF410F400]

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [C0, D2, 10, F4, 80, A5, 10, ...] {RCL DL, 0x10; HLT ; AND BYTE [EBP-0x569f0bf0], 0x10; HLT }
.text ntoskrnl.exe!_abnormal_termination + 290 804E28EC 4 Bytes JMP 6A2BF410
.text ntoskrnl.exe!_abnormal_termination + 31C 804E2978 1 Byte [40]
.text ntoskrnl.exe!_abnormal_termination + 440 804E2A9C 12 Bytes [40, CE, 10, F4, C0, CA, 10, ...] {INC EAX; INTO ; ADC AH, DH; ROR DL, 0x10; HLT ; ADD CL, CL; ADC AH, DH}
init C:\WINDOWS\system32\drivers\tiumflt.sys entry point in "init" section [0xFAFE0E00]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [FAC73610] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [FAC73650] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [FAC73300] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [FAC73360] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [FAC73300] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [FAC73360] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [FAC73610] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [FAC73650] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [FAC73610] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [FAC73360] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [FAC73300] \??\C:\WINDOWS\system32\drivers\OAnet.sys (OA Helper Driver/Tall Emu Pty Ltd)

---- Devices - GMER 1.0.15 ----

Device \Driver\Tcpip \Device\Ip OAmon.sys (TDI Helper Driver/Tall Emu)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Tcp OAmon.sys (TDI Helper Driver/Tall Emu)

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Udp OAmon.sys (TDI Helper Driver/Tall Emu)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\RawIp OAmon.sys (TDI Helper Driver/Tall Emu)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys (TDI Helper Driver/Tall Emu)

---- EOF - GMER 1.0.15 ----

If we don't change the direction we are going,
We are likely to end up where we are headed.

#4 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:33 AM

Posted 17 February 2010 - 09:41 PM

Hello, Sashacat.
You're welcome in advance. smile.gif We'll take care of the yahoo and online armor in a bit. First, let's run Combofix.

Next, please download ComboFix from one of these locations:* IMPORTANT !!! Save ComboFix.exe to your Desktop as SashacatCF.exe
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on SashacatCF.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply, along with any symptoms that are present after it runs.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#5 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 18 February 2010 - 12:16 AM

etavares, (and boopme too)
THANK YOU! smile.gif THANK YOU! smile.gif THANK YOU! smile.gif (Yes, I'm shouting) smile.gif
Followed your most recent instructions exactly, and I think (knock on wood) I am free of symptoms.
rundll32.exe is no longer running in Task Mngr.

Also, a big THANKS to Gmer for ComboFix !!!
(Just as I ran ComboFix, [I had just downloaded it and disabled all recommended items], I was notified of an update to ComboFix so I got the latest update on that.)

Don't know if this matters or not, but before I ran ComboFix, I did read the topic about disabling things (antivirus, firewalls, etc) and in addition to following the instructions for disabling AVG Free 9, I checked in the places I was aware of (Task Mngr., Process Exlorer, services.msc and msconfig) to make sure there was nothing running for the Online Armor firewall that I had previously uninstalled.
The two entries in services.msc for Online Armor did NOT (still don't) show as "Started", and they BOTH show "disabled",
but I saw the notation in the ComboFix log that says Online Armor Firewall "enabled". That struck me as odd.......

ComboFix log is copied/pasted below:

ComboFix 10-02-16.03 - Lisa Hill 02/17/2010 23:13:25.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.191.72 [GMT -5:00]
Running from: c:\documents and settings\Lisa Hill\Desktop\SashacatCF.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\senekariqpxmtk.dat
c:\windows\Tasks\huvgcpzw.job

.
((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))
.

2010-02-15 20:32 . 2010-02-15 20:33 -------- d-----w- c:\program files\ERUNT
2010-02-11 19:29 . 2010-02-11 19:29 -------- d-----w- c:\windows\system32\Adobe
2010-02-09 20:04 . 2010-02-09 20:04 -------- d-----w- c:\program files\ESET
2010-02-05 18:23 . 2010-02-05 18:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 14:37 . 2009-07-11 10:17 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-01 14:37 . 2009-07-11 10:59 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-01 14:37 . 2009-07-11 10:17 200784 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-01 14:33 . 2010-02-06 16:38 -------- d-----w- c:\program files\a-squared Free
2010-02-01 03:49 . 2010-02-01 03:49 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\Malwarebytes
2010-02-01 03:28 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 03:28 . 2010-02-01 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-01 03:28 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-31 23:05 . 2010-01-31 23:05 52224 ----a-w- c:\documents and settings\Lisa Hill\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-31 22:56 . 2010-02-16 02:36 117760 ----a-w- c:\documents and settings\Lisa Hill\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-31 22:54 . 2010-01-31 22:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-31 22:49 . 2010-02-16 02:35 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-31 22:49 . 2010-01-31 22:49 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\SUPERAntiSpyware.com
2010-01-31 22:46 . 2010-01-31 22:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-31 20:35 . 2010-01-31 20:35 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\WinPatrol
2010-01-31 20:35 . 2006-01-28 00:53 48 ----a-w- c:\documents and settings\Lisa Hill\Application Data\WinPatrol\Autoexec.bat
2010-01-31 20:34 . 2010-01-31 20:34 -------- d-----w- c:\program files\BillP Studios
2010-01-28 15:58 . 2010-01-28 15:59 -------- d-----w- c:\program files\ShowMyPC
2010-01-28 15:41 . 2010-01-28 15:41 -------- d-----w- c:\documents and settings\Lisa Hill\Tracing
2010-01-28 15:27 . 2010-01-28 15:27 -------- d-----w- c:\program files\Microsoft
2010-01-28 15:26 . 2010-01-28 15:26 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-01-28 15:05 . 2010-01-28 15:05 -------- d-----w- c:\program files\Common Files\Windows Live
2010-01-28 13:47 . 2010-02-05 22:19 -------- d-----w- c:\documents and settings\Lisa Hill\Local Settings\Application Data\Temp
2010-01-27 12:57 . 2010-02-04 13:01 -------- d-----w- c:\program files\K9
2010-01-24 18:28 . 2010-01-24 21:22 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-24 15:26 . 2010-01-24 15:26 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\AVG9
2010-01-23 14:03 . 2010-01-23 14:03 -------- d-----w- c:\program files\Common Files\HP
2010-01-23 14:02 . 2010-01-23 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-01-23 14:02 . 2010-01-23 14:02 -------- d-----w- c:\program files\Winamp Detect
2010-01-23 05:25 . 2010-01-23 05:25 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-01-23 05:16 . 2007-11-02 02:28 970752 ----a-w- c:\windows\system32\hpotiop5.dll
2010-01-23 05:16 . 2007-11-02 02:28 303104 ----a-w- c:\windows\system32\hpovst12.dll
2010-01-23 05:16 . 2007-11-02 02:28 364544 ----a-w- c:\windows\system32\hppldcoi.dll
2010-01-23 05:16 . 2007-11-02 02:28 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-01-23 05:16 . 2007-11-02 02:28 729088 ----a-w- c:\windows\system32\hpowiax5.dll
2010-01-23 05:10 . 2010-01-24 21:36 166269 ----a-w- c:\windows\hpoins21.dat
2010-01-23 05:10 . 2008-02-13 09:15 7262 ------w- c:\windows\hpomdl21.dat
2010-01-21 18:44 . 2010-01-21 18:44 3472 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-21 18:32 . 2010-01-21 18:34 -------- d-----w- c:\windows\Logs
2010-01-21 00:56 . 2010-01-21 05:12 -------- d-----w- C:\$AVG

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 04:25 . 2005-02-21 04:52 -------- d-----w- c:\program files\Paint Shop Pro 6
2010-02-17 04:25 . 2004-10-09 14:59 -------- d-----w- c:\program files\Microsoft Publisher
2010-02-17 04:25 . 2004-10-09 15:08 -------- d-----w- c:\program files\Avery Wizard
2010-01-30 23:24 . 2005-01-29 01:57 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-28 15:35 . 2004-10-03 15:56 184232 ----a-w- c:\documents and settings\Lisa Hill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-28 15:31 . 2005-02-06 17:06 -------- d-----w- c:\program files\MSN Messenger
2010-01-28 15:24 . 2008-08-29 21:24 -------- d-----w- c:\program files\Windows Live
2010-01-27 20:45 . 2005-02-21 04:44 -------- d-----w- c:\program files\Paint Shop Pro 5
2010-01-24 16:59 . 2010-01-11 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-23 14:02 . 2005-12-10 00:37 -------- d-----w- c:\program files\Winamp
2010-01-23 01:37 . 2005-01-29 05:01 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\HP
2010-01-22 23:53 . 2010-01-14 15:37 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-01-21 00:48 . 2008-04-26 01:11 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-21 00:48 . 2008-04-26 01:11 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-21 00:48 . 2008-04-26 01:11 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-21 00:48 . 2007-01-09 06:10 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-21 00:47 . 2008-04-26 01:10 -------- d-----w- c:\program files\AVG
2010-01-17 23:53 . 2010-01-17 23:53 -------- d-----w- c:\program files\Walmart MP3 Music Downloads
2010-01-17 13:39 . 2010-01-17 13:39 -------- d-sh--w- c:\documents and settings\All Users\Application Data\System Restore
2010-01-16 21:59 . 2010-01-16 21:59 -------- d-----w- c:\program files\ffdshow
2010-01-16 21:57 . 2010-01-16 21:57 -------- d-----w- c:\program files\PlayFLV
2010-01-16 20:10 . 2004-05-07 04:44 -------- d-----w- c:\program files\Hewlett-Packard
2010-01-16 19:07 . 2004-05-07 03:48 -------- d-----w- c:\program files\HPQ
2010-01-16 19:07 . 2003-07-16 13:08 76487 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2010-01-14 19:04 . 2010-01-14 19:04 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\K9
2010-01-14 16:35 . 2010-01-14 16:24 19573 ----a-w- c:\windows\hpqins13.dat
2010-01-14 16:14 . 2010-01-14 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2010-01-14 15:19 . 2010-01-14 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2010-01-13 08:31 . 2010-01-13 08:31 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-01-13 08:31 . 2010-01-13 08:31 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-13 08:20 . 2010-01-13 08:20 -------- d-----w- c:\program files\MSXML 6.0
2010-01-13 03:36 . 2010-01-13 03:33 69 ----a-w- c:\documents and settings\Lisa Hill\jagex_runescape_preferences2.dat
2010-01-13 03:36 . 2008-08-30 03:59 39 ----a-w- c:\documents and settings\Lisa Hill\jagex_runescape_preferences.dat
2010-01-13 00:11 . 2004-12-25 04:31 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\AdobeUM
2010-01-12 23:39 . 2010-01-12 23:39 -------- d-----w- c:\documents and settings\LocalService\Application Data\Softland
2010-01-12 23:39 . 2010-01-12 23:39 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\Softland
2010-01-12 23:38 . 2010-01-12 23:38 -------- d-----w- c:\program files\Softland
2010-01-09 17:43 . 2010-01-09 17:43 -------- d-----w- c:\program files\CCleaner
2010-01-09 17:42 . 2010-01-09 17:42 -------- d-----w- c:\program files\VS Revo Group
2010-01-09 15:20 . 2008-08-29 18:59 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\Motive
2010-01-05 21:24 . 2010-01-12 23:38 21704 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-01-05 21:24 . 2010-01-12 23:38 18632 ----a-w- c:\windows\system32\dopdfmi7.dll
2009-11-21 16:36 . 2003-03-31 02:00 470528 ----a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2003-10-30 13:40 88363 ----a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-01-21 00:47 2033432 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 04:56 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 12:56 2002160 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPatrol]
2009-10-10 21:07 320832 ------w- c:\program files\BillP Studios\WinPatrol\WinPatrol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"ERSvc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mshta.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgcsrvx.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/25/2008 8:11 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/25/2008 8:11 PM 360584]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2/1/2010 9:37 AM 200784]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2/1/2010 9:37 AM 24656]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2/1/2010 9:37 AM 29776]
S2 mrtRate;mrtRate; [x]
S3 apusbsnt;Sierra Wireless USB Modem Device Driver;c:\windows\system32\DRIVERS\apusbsnt.sys --> c:\windows\system32\DRIVERS\apusbsnt.sys [?]
S3 ECnvtBox;Embroidery Conversion Box Plus;c:\windows\system32\drivers\ECnvtBox.sys [1/8/2005 1:23 PM 37818]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [9/14/2006 4:45 PM 92160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.wftv.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: &Search
FF - ProfilePath - c:\documents and settings\Lisa Hill\Application Data\Mozilla\Firefox\Profiles\gct4q43z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
Notify-!SASWinLogon - (no file)
Notify-avgrsstarter - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-17 23:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(380)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\bmwebcfg.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-17 23:41:34 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-18 04:41

Pre-Run: 18,918,879,232 bytes free
Post-Run: 18,801,905,664 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - B58FE40881DC4DE219806A3402C47938

If we don't change the direction we are going,
We are likely to end up where we are headed.

#6 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 18 February 2010 - 01:45 PM

I am happy to report the rundll32.exe has not come back in Task Mngr since my prev post smile.gif smile.gif smile.gif


There are changes I would like to make, but I will restrain myself so as not to throw a wrench in the monkeyworks (until AFTER I get the go ahead from somebody on the Malware Response Team about removing the Yahoo Toolbar entry and the Online Armor entry; programs I no longer have; they were uninstalled).

The changes I would like to make are:
  • Change from AVG Free to Avast (AVG uses up alot of resources)
  • Install the free ZoneAlarm firewall.
  • Update Adobe Reader to the most recent version (and remove old ver)
  • Update Java (and remove old ver)







If we don't change the direction we are going,
We are likely to end up where we are headed.

#7 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:33 AM

Posted 18 February 2010 - 06:30 PM

Hello, Sashacat.
Glad to hear it's running better! And you guessed 3 things that I wanted to do....repair/uninstall Online Armor, update Java, and update Adobe Reader. We can switch to AVG if you want. Before we do all this, let's clean up some mess and get a second opinion from ESET that the virus is gone. If malware is still present, it can throw a BIG monkey wrench into changing security programs.

Also...thanks to sUBs for Combofix!

Now...I see an odd policy setting that keeps My Documents and My Photos out of your start menu. Did you do this intentionally? Some malware modifies some system settings. If you did want that, no worries. If you didn't, we can fix. Please let me know.



One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you do decide to proceed, please continue with the fix below.



Step 1

I'd like us to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push



Step 2

In your reply, please answer my questions and post the ESET log and also a fresh DDS log.

If we look good, I'll give you some instructions to try to remove Online Armor. It's still running, even though the add/remove program entry is gone.

Thanks!


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#8 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 20 February 2010 - 01:42 PM

QUOTE(etavares @ Feb 18 2010, 06:30 PM) View Post
Now...I see an odd policy setting that keeps My Documents and My Photos out of your start menu. Did you do this intentionally? Some malware modifies some system settings. If you did want that, no worries. If you didn't, we can fix. Please let me know.



Yep, I did that on purpose. Start menus that are 8 miles long with alot of pop-out menus make me crazy.
I used Tweak UI and have it set to NOT SHOW: My Documents, My Pictures, and Recent Documents.

I absolutely 100% agree with you about reformat and reinstall Windows, and when the Windows CD is available, that's normally my first choice.
Can't find the Windows CD right now, so I'm in "fixing" mode for now.
For safety reasons, I never store anything IMPORTANT on a computer, and never store passwords for anything related to financial transactions.

I will go do ESET and DDS and report back.
Thanks smile.gif
If we don't change the direction we are going,
We are likely to end up where we are headed.

#9 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 20 February 2010 - 08:14 PM

Hello etavares smile.gif

thumbup.gif ESET scan came up clean: thumbup.gif
Scanned Files: 59984
Infected Files: 0
Cleaned Files: 0
Total Scan Time: 03:21:57
Scan Status: Finished
There was no "List of Found Threats" or option to "Export to text file".



DDS results: (Attach.txt file is attached)

DDS (Ver_09-12-01.01) - NTFSx86
Run by Lisa Hill at 19:37:51.28 on Sat 02/20/2010
Internet Explorer: 6.0.2900.2180

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Lisa Hill\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.wftv.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
uPolicies-explorer: NoActiveDesktop = 01000000
IE: &Search
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522}
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lisahi~1\applic~1\mozilla\firefox\profiles\gct4q43z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R? a2free;a-squared Free Service
R? apusbsnt;Sierra Wireless USB Modem Device Driver
R? ECnvtBox;Embroidery Conversion Box Plus
R? mrtRate;mrtRate
R? NWUSBPort2;Novatel Wireless USB Status2 Port Driver
R? OAcat;Online Armor Helper Service
R? SASENUM;SASENUM
R? SvcOnlineArmor;Online Armor
R? Viewpoint Manager Service;Viewpoint Manager Service
S? avg9emc;AVG Free E-mail Scanner
S? avg9wd;AVG Free WatchDog
S? AvgLdx86;AVG AVI Loader Driver x86
S? AvgMfx86;AVG On-access Scanner Minifilter Driver x86
S? AvgTdiX;AVG Free Network Redirector
S? OADevice;OADriver
S? OAmon;OAmon
S? OAnet;OAnet
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL

=============== Created Last 30 ================

2010-02-19 02:38:43 0 d-----w- c:\program files\Process Explorer
2010-02-18 04:09:54 0 d-sha-r- C:\cmdcons
2010-02-18 04:05:55 77312 ----a-w- c:\windows\MBR.exe
2010-02-18 04:05:55 261632 ----a-w- c:\windows\PEV.exe
2010-02-18 04:05:55 161792 ----a-w- c:\windows\SWREG.exe
2010-02-18 04:05:54 98816 ----a-w- c:\windows\sed.exe
2010-02-11 19:29:07 0 d-----w- c:\windows\system32\Adobe
2010-02-09 20:04:13 0 d-----w- c:\program files\ESET
2010-02-05 18:23:49 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 14:37:46 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-01 14:37:45 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-01 14:37:25 200784 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-01 14:33:59 0 d-----w- c:\program files\a-squared Free
2010-02-01 03:49:03 0 d-----w- c:\docume~1\lisahi~1\applic~1\Malwarebytes
2010-02-01 03:28:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 03:28:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-01 03:28:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-31 22:54:23 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:49:39 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-31 22:49:38 0 d-----w- c:\docume~1\lisahi~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:46:54 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-31 20:56:32 1744 ---ha-w- c:\windows\system32\dobijuzi
2010-01-31 20:35:10 0 d-----w- c:\docume~1\lisahi~1\applic~1\WinPatrol
2010-01-31 20:34:11 0 d-----w- c:\program files\BillP Studios
2010-01-28 15:58:12 0 d-----w- c:\program files\ShowMyPC
2010-01-28 15:41:16 0 d-----w- c:\documents and settings\lisa hill\Tracing
2010-01-28 15:27:05 0 d-----w- c:\program files\Microsoft
2010-01-28 15:26:18 0 d-----w- c:\program files\Windows Live SkyDrive
2010-01-28 15:05:16 0 d-----w- c:\program files\common files\Windows Live
2010-01-27 12:57:57 0 d-----w- c:\program files\K9
2010-01-24 18:28:57 0 d-----w- c:\windows\SxsCaPendDel
2010-01-24 15:26:05 0 d-----w- c:\docume~1\lisahi~1\applic~1\AVG9
2010-01-23 14:03:57 0 d-----w- c:\program files\common files\HP
2010-01-23 14:02:06 0 d-----w- c:\program files\Winamp Detect
2010-01-23 05:25:22 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-01-23 05:16:38 970752 ----a-w- c:\windows\system32\hpotiop5.dll
2010-01-23 05:16:37 364544 ----a-w- c:\windows\system32\hppldcoi.dll
2010-01-23 05:16:37 303104 ----a-w- c:\windows\system32\hpovst12.dll
2010-01-23 05:16:36 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-01-23 05:16:35 729088 ----a-w- c:\windows\system32\hpowiax5.dll
2010-01-23 05:10:17 166269 ----a-w- c:\windows\hpoins21.dat
2010-01-23 05:10:16 7262 ------w- c:\windows\hpomdl21.dat

==================== Find3M ====================

2010-01-30 23:24:07 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-27 19:13:56 30868 ----a-w- c:\windows\fonts\IllegalEdding.ttf
2010-01-27 19:13:08 100572 ----a-w- c:\windows\fonts\Degrassi.ttf
2010-01-27 19:12:36 53352 ----a-w- c:\windows\fonts\Searfont.ttf
2010-01-27 19:11:42 68352 ----a-w- c:\windows\fonts\Rufa.ttf
2010-01-21 18:44:18 3472 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-21 00:48:40 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-21 00:48:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-21 00:48:39 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-19 18:38:28 66536 ----a-w- c:\windows\fonts\PressWriter_Symbols.ttf
2010-01-14 16:35:44 19573 ----a-w- c:\windows\hpqins13.dat
2010-01-13 08:31:43 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-01-13 08:31:21 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-13 03:36:09 69 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences2.dat
2010-01-13 03:36:09 39 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences.dat
2010-01-05 21:24:16 21704 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-01-05 21:24:14 18632 ----a-w- c:\windows\system32\dopdfmi7.dll

============= FINISH: 19:39:54.04 ===============



The main reason that I want to change from AVG Free to Avast is because AVG has EIGHT separate processes running in Task Mngr (and that's when it's NOT updating), plus the two items shown in services.msc and the AVG Safe Search (Firefox add-on). I'm hoping that Avast will use significantly less resources.

smile.gif thanks


Attached Files


If we don't change the direction we are going,
We are likely to end up where we are headed.

#10 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:33 AM

Posted 21 February 2010 - 07:29 AM

Hello, Sashacat.

Great News! smile.gif

OK, let's get to work. We'll work on your security programs and remove some leftovers.


Step 1

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
DDS::
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Step 2

Please go to Start --> Run and type this in at the prompt:
sc delete mrtRate

Then click OK.



Step 3

First, download Avast! and save the installer to your comptuer. Don't run it yet!
http://www.avast.com/free-antivirus-download

For Online Armor, please download it as well. With incomplete installs, sometimes the easiest fix is to reinstall then uninstall again.
http://www.tallemu.com/products-online-armor-free.php

Again, please save it to your desktop for now.



Step 4

Important: please disconnect your computer from the internet by pulling the internet cable out or disabling wireless for now. An unprotected computer connected to the internet can literally be infected in seconds.

Go to Start --> Control Panel --> Add/Remove Programs and uninstall:

A-squared Free 4.5
AVG Free 9.0


Next, install Avast!

When installed, plug your network cable back in or sign into wireless. Immediately update your virus definitions!



Step 6

Now, install Online Armor.

Reboot if it doesn't autmatically do that after the install.

Now remove Online Armor from Add/Remove Programs.



Step 5

Please reply back with:
  • CF Log from Step 1
  • A fresh DDS log
etavares

EDIT: type in step number

Edited by etavares, 21 February 2010 - 07:29 AM.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#11 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 21 February 2010 - 10:13 PM

Hello etavares smile.gif

I'd love to know half as much as you do. smile.gif It's awesome when people like you, who possess THAT much knowledge, are NICE to people, and use that knowledge to help others. I have a TREMENDOUS of respect for you and the other members of this forum.

Thanks for your reply/instructions, and for including the info to type into notepad for the CF thing. I'm glad you had provisions for uninstalling a-squared, because that was another thing I wanted to remove.

I followed your steps and did EVERYTHING EXCEPT uninstalling Online Armor free firewall. The reason I did NOT uninstall it was because after getting rid of AVG Free antivirus, and installing Avast, the system was better (not as bogged down) than it was before (even WITH Online Armor installed and running), and so far, I think I like it better than the ZoneAlarm free firewall.

Before doing all of this, I had printed your instructions in .pdf file format, so the instructions would be available for me when I disabled the wireless connection and removed the USB wireless thingy. Strangely, after a-squared and AVG were uninstalled, and Avast and Online Armor were installed, my old (outdated) Adobe Reader 7.0 wouldn't work, and I still needed the instructions, so I uninstalled Acrobat Reader 7.0 and installed the latest version of Adobe Reader 9.3, and was then able to view the instructions again. I also uninstalled WinPatrol, because Online Armor seems to do a good job of policing what programs run.

Here are the CF and DDS logs:

ComboFix 10-02-20.04 - Lisa Hill 02/21/2010 9:31.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.191.32 [GMT -5:00]
Running from: c:\downloads xfer outta here\ComboFix.exe
Command switches used :: c:\downloads xfer outta here\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.

((((((((((((((((((((((((( Files Created from 2010-01-21 to 2010-02-21 )))))))))))))))))))))))))))))))
.

2010-02-19 02:38 . 2010-02-19 02:39 -------- d-----w- c:\program files\Process Explorer
2010-02-15 20:32 . 2010-02-15 20:33 -------- d-----w- c:\program files\ERUNT
2010-02-11 19:29 . 2010-02-11 19:29 -------- d-----w- c:\windows\system32\Adobe
2010-02-09 20:04 . 2010-02-09 20:04 -------- d-----w- c:\program files\ESET
2010-02-05 18:23 . 2010-02-05 18:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 14:37 . 2009-07-11 10:17 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-01 14:37 . 2009-07-11 10:59 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-01 14:37 . 2009-07-11 10:17 200784 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-01 14:33 . 2010-02-06 16:38 -------- d-----w- c:\program files\a-squared Free
2010-02-01 03:49 . 2010-02-01 03:49 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\Malwarebytes
2010-02-01 03:28 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 03:28 . 2010-02-01 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-01 03:28 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-31 23:05 . 2010-01-31 23:05 52224 ----a-w- c:\documents and settings\Lisa Hill\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-31 22:56 . 2010-02-16 02:36 117760 ----a-w- c:\documents and settings\Lisa Hill\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-31 22:54 . 2010-01-31 22:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-31 22:49 . 2010-02-16 02:35 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-31 22:49 . 2010-01-31 22:49 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\SUPERAntiSpyware.com
2010-01-31 22:46 . 2010-01-31 22:46 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-31 20:35 . 2010-01-31 20:35 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\WinPatrol
2010-01-31 20:35 . 2006-01-28 00:53 48 ----a-w- c:\documents and settings\Lisa Hill\Application Data\WinPatrol\Autoexec.bat
2010-01-31 20:34 . 2010-01-31 20:34 -------- d-----w- c:\program files\BillP Studios
2010-01-28 15:58 . 2010-01-28 15:59 -------- d-----w- c:\program files\ShowMyPC
2010-01-28 15:41 . 2010-01-28 15:41 -------- d-----w- c:\documents and settings\Lisa Hill\Tracing
2010-01-28 15:27 . 2010-01-28 15:27 -------- d-----w- c:\program files\Microsoft
2010-01-28 15:26 . 2010-01-28 15:26 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-01-28 15:05 . 2010-01-28 15:05 -------- d-----w- c:\program files\Common Files\Windows Live
2010-01-28 13:47 . 2010-02-05 22:19 -------- d-----w- c:\documents and settings\Lisa Hill\Local Settings\Application Data\Temp
2010-01-27 12:57 . 2010-02-04 13:01 -------- d-----w- c:\program files\K9
2010-01-24 18:28 . 2010-01-24 21:22 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-24 15:26 . 2010-01-24 15:26 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\AVG9
2010-01-23 14:03 . 2010-01-23 14:03 -------- d-----w- c:\program files\Common Files\HP
2010-01-23 14:02 . 2010-01-23 14:02 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2010-01-23 14:02 . 2010-01-23 14:02 -------- d-----w- c:\program files\Winamp Detect
2010-01-23 05:25 . 2010-01-23 05:25 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2010-01-23 05:16 . 2007-11-02 02:28 970752 ----a-w- c:\windows\system32\hpotiop5.dll
2010-01-23 05:16 . 2007-11-02 02:28 303104 ----a-w- c:\windows\system32\hpovst12.dll
2010-01-23 05:16 . 2007-11-02 02:28 364544 ----a-w- c:\windows\system32\hppldcoi.dll
2010-01-23 05:16 . 2007-11-02 02:28 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-01-23 05:16 . 2007-11-02 02:28 729088 ----a-w- c:\windows\system32\hpowiax5.dll
2010-01-23 05:10 . 2010-01-24 21:36 166269 ----a-w- c:\windows\hpoins21.dat
2010-01-23 05:10 . 2008-02-13 09:15 7262 ------w- c:\windows\hpomdl21.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 04:25 . 2005-02-21 04:52 -------- d-----w- c:\program files\Paint Shop Pro 6
2010-02-17 04:25 . 2004-10-09 14:59 -------- d-----w- c:\program files\Microsoft Publisher
2010-02-17 04:25 . 2004-10-09 15:08 -------- d-----w- c:\program files\Avery Wizard
2010-01-30 23:24 . 2005-01-29 01:57 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-28 15:35 . 2004-10-03 15:56 184232 ----a-w- c:\documents and settings\Lisa Hill\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-28 15:31 . 2005-02-06 17:06 -------- d-----w- c:\program files\MSN Messenger
2010-01-28 15:24 . 2008-08-29 21:24 -------- d-----w- c:\program files\Windows Live
2010-01-27 20:45 . 2005-02-21 04:44 -------- d-----w- c:\program files\Paint Shop Pro 5
2010-01-24 16:59 . 2010-01-11 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-23 14:02 . 2005-12-10 00:37 -------- d-----w- c:\program files\Winamp
2010-01-23 01:37 . 2005-01-29 05:01 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\HP
2010-01-22 23:53 . 2010-01-14 15:37 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2010-01-21 18:44 . 2010-01-21 18:44 3472 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-21 00:48 . 2008-04-26 01:11 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-21 00:48 . 2008-04-26 01:11 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-21 00:48 . 2008-04-26 01:11 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-21 00:48 . 2007-01-09 06:10 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-21 00:47 . 2008-04-26 01:10 -------- d-----w- c:\program files\AVG
2010-01-17 23:53 . 2010-01-17 23:53 -------- d-----w- c:\program files\Walmart MP3 Music Downloads
2010-01-17 13:39 . 2010-01-17 13:39 -------- d-sh--w- c:\documents and settings\All Users\Application Data\System Restore
2010-01-16 21:59 . 2010-01-16 21:59 -------- d-----w- c:\program files\ffdshow
2010-01-16 21:57 . 2010-01-16 21:57 -------- d-----w- c:\program files\PlayFLV
2010-01-16 20:10 . 2004-05-07 04:44 -------- d-----w- c:\program files\Hewlett-Packard
2010-01-16 19:07 . 2004-05-07 03:48 -------- d-----w- c:\program files\HPQ
2010-01-16 19:07 . 2003-07-16 13:08 76487 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2010-01-14 19:04 . 2010-01-14 19:04 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\K9
2010-01-14 16:35 . 2010-01-14 16:24 19573 ----a-w- c:\windows\hpqins13.dat
2010-01-14 16:14 . 2010-01-14 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2010-01-14 15:19 . 2010-01-14 15:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2010-01-13 08:31 . 2010-01-13 08:31 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-01-13 08:31 . 2010-01-13 08:31 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-13 08:20 . 2010-01-13 08:20 -------- d-----w- c:\program files\MSXML 6.0
2010-01-13 03:36 . 2010-01-13 03:33 69 ----a-w- c:\documents and settings\Lisa Hill\jagex_runescape_preferences2.dat
2010-01-13 03:36 . 2008-08-30 03:59 39 ----a-w- c:\documents and settings\Lisa Hill\jagex_runescape_preferences.dat
2010-01-13 00:11 . 2004-12-25 04:31 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\AdobeUM
2010-01-12 23:39 . 2010-01-12 23:39 -------- d-----w- c:\documents and settings\LocalService\Application Data\Softland
2010-01-12 23:39 . 2010-01-12 23:39 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\Softland
2010-01-12 23:38 . 2010-01-12 23:38 -------- d-----w- c:\program files\Softland
2010-01-09 17:43 . 2010-01-09 17:43 -------- d-----w- c:\program files\CCleaner
2010-01-09 17:42 . 2010-01-09 17:42 -------- d-----w- c:\program files\VS Revo Group
2010-01-09 15:20 . 2008-08-29 18:59 -------- d-----w- c:\documents and settings\Lisa Hill\Application Data\Motive
2010-01-05 21:24 . 2010-01-12 23:38 21704 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-01-05 21:24 . 2010-01-12 23:38 18632 ----a-w- c:\windows\system32\dopdfmi7.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2003-10-30 13:40 88363 ----a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 04:56 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-01-05 12:56 2002160 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPatrol]
2009-10-10 21:07 320832 ------w- c:\program files\BillP Studios\WinPatrol\WinPatrol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"ERSvc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mshta.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgcsrvx.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/25/2008 8:11 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/25/2008 8:11 PM 360584]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2/1/2010 9:37 AM 200784]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2/1/2010 9:37 AM 24656]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [2/1/2010 9:37 AM 29776]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R4 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/20/2010 7:47 PM 285392]
S2 mrtRate;mrtRate; [x]
S3 apusbsnt;Sierra Wireless USB Modem Device Driver;c:\windows\system32\DRIVERS\apusbsnt.sys --> c:\windows\system32\DRIVERS\apusbsnt.sys [?]
S3 ECnvtBox;Embroidery Conversion Box Plus;c:\windows\system32\drivers\ECnvtBox.sys [1/8/2005 1:23 PM 37818]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [9/14/2006 4:45 PM 92160]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S4 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2/1/2010 9:34 AM 1858144]
S4 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [1/20/2010 7:47 PM 906520]
S4 OAcat;Online Armor Helper Service;"c:\program files\Tall Emu\Online Armor\OAcat.exe" --> c:\program files\Tall Emu\Online Armor\OAcat.exe [?]
S4 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe --> c:\program files\Tall Emu\Online Armor\oasrv.exe [?]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/14/2007 9:47 AM 24652]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.wftv.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: &Search
FF - ProfilePath - c:\documents and settings\Lisa Hill\Application Data\Mozilla\Firefox\Profiles\gct4q43z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-21 09:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(432)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3140)
c:\windows\System32\shdoclc.dll
.
Completion time: 2010-02-21 09:52:17
ComboFix-quarantined-files.txt 2010-02-21 14:52
ComboFix2.txt 2010-02-18 04:41

Pre-Run: 18,697,461,760 bytes free
Post-Run: 18,687,225,856 bytes free

- - End Of File - - 3062C7D74238E87E5FBB7CA7FE7A9C0F
------------------------------------------------------------------------------------------------------------------------------------------


DDS (Ver_09-12-01.01) - NTFSx86
Run by Lisa Hill at 20:43:10.57 on Sun 02/21/2010
Internet Explorer: 6.0.2900.2180

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Tall Emu\Online Armor\OAui.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Downloads Xfer Outta Here\dds.scr
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.wftv.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [@OnlineArmor GUI] "c:\program files\tall emu\online armor\OAui.exe"
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lisahi~1\applic~1\mozilla\firefox\profiles\gct4q43z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R? apusbsnt;Sierra Wireless USB Modem Device Driver
R? ECnvtBox;Embroidery Conversion Box Plus
R? NWUSBPort2;Novatel Wireless USB Status2 Port Driver
R? SASENUM;SASENUM
R? Viewpoint Manager Service;Viewpoint Manager Service
S? aswFsBlk;aswFsBlk
S? aswSP;aswSP
S? avast! Antivirus;avast! Antivirus
S? avast! Mail Scanner;avast! Mail Scanner
S? avast! Web Scanner;avast! Web Scanner
S? OAcat;Online Armor Helper Service
S? OADevice;OADriver
S? OAmon;OAmon
S? OAnet;OAnet
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? SvcOnlineArmor;Online Armor

=============== Created Last 30 ================

2010-02-21 16:56:26 0 d-----w- c:\docume~1\lisahi~1\applic~1\OnlineArmor
2010-02-21 16:56:26 0 d-----w- c:\docume~1\alluse~1\applic~1\OnlineArmor
2010-02-21 16:55:35 0 d-----w- c:\program files\Tall Emu
2010-02-21 16:36:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-02-19 02:38:43 0 d-----w- c:\program files\Process Explorer
2010-02-18 04:09:54 0 d-sha-r- C:\cmdcons
2010-02-18 04:05:55 77312 ----a-w- c:\windows\MBR.exe
2010-02-18 04:05:55 261632 ----a-w- c:\windows\PEV.exe
2010-02-18 04:05:55 161792 ----a-w- c:\windows\SWREG.exe
2010-02-18 04:05:54 98816 ----a-w- c:\windows\sed.exe
2010-02-11 19:29:07 0 d-----w- c:\windows\system32\Adobe
2010-02-09 20:04:13 0 d-----w- c:\program files\ESET
2010-02-05 18:23:49 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 14:37:46 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-01 14:37:45 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-01 14:37:25 223312 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-01 03:49:03 0 d-----w- c:\docume~1\lisahi~1\applic~1\Malwarebytes
2010-02-01 03:28:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 03:28:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-01 03:28:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-31 22:54:23 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:49:39 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-31 22:49:38 0 d-----w- c:\docume~1\lisahi~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:46:54 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-31 20:56:32 1744 ---ha-w- c:\windows\system32\dobijuzi
2010-01-31 20:35:10 0 d-----w- c:\docume~1\lisahi~1\applic~1\WinPatrol
2010-01-28 15:58:12 0 d-----w- c:\program files\ShowMyPC
2010-01-28 15:41:16 0 d-----w- c:\documents and settings\lisa hill\Tracing
2010-01-28 15:27:05 0 d-----w- c:\program files\Microsoft
2010-01-28 15:26:18 0 d-----w- c:\program files\Windows Live SkyDrive
2010-01-28 15:05:16 0 d-----w- c:\program files\common files\Windows Live
2010-01-27 12:57:57 0 d-----w- c:\program files\K9
2010-01-24 18:28:57 0 d-----w- c:\windows\SxsCaPendDel
2010-01-23 14:03:57 0 d-----w- c:\program files\common files\HP
2010-01-23 14:02:06 0 d-----w- c:\program files\Winamp Detect
2010-01-23 05:25:22 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-01-23 05:16:38 970752 ----a-w- c:\windows\system32\hpotiop5.dll
2010-01-23 05:16:37 364544 ----a-w- c:\windows\system32\hppldcoi.dll
2010-01-23 05:16:37 303104 ----a-w- c:\windows\system32\hpovst12.dll
2010-01-23 05:16:36 309760 ----a-w- c:\windows\system32\difxapi.dll
2010-01-23 05:16:35 729088 ----a-w- c:\windows\system32\hpowiax5.dll
2010-01-23 05:10:17 166269 ----a-w- c:\windows\hpoins21.dat
2010-01-23 05:10:16 7262 ------w- c:\windows\hpomdl21.dat

==================== Find3M ====================

2010-01-30 23:24:07 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-27 19:13:56 30868 ----a-w- c:\windows\fonts\IllegalEdding.ttf
2010-01-27 19:13:08 100572 ----a-w- c:\windows\fonts\Degrassi.ttf
2010-01-27 19:12:36 53352 ----a-w- c:\windows\fonts\Searfont.ttf
2010-01-27 19:11:42 68352 ----a-w- c:\windows\fonts\Rufa.ttf
2010-01-21 18:44:18 3472 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-19 18:38:28 66536 ----a-w- c:\windows\fonts\PressWriter_Symbols.ttf
2010-01-14 16:35:44 19573 ----a-w- c:\windows\hpqins13.dat
2010-01-13 08:31:43 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-01-13 08:31:21 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-13 03:36:09 69 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences2.dat
2010-01-13 03:36:09 39 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences.dat
2010-01-05 21:24:16 21704 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-01-05 21:24:14 18632 ----a-w- c:\windows\system32\dopdfmi7.dll

============= FINISH: 21:07:10.40 ===============

---------------------------------------------------------------------------------------------------------------------------------------

I know my Java is outdated, and I've downloaded (but not installed yet) the latest Java (ver 6 update 18), so I'll still need to do that.


Thanks again, for EVERYTHING smile.gif smile.gif smile.gif


Attached Files


If we don't change the direction we are going,
We are likely to end up where we are headed.

#12 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:33 AM

Posted 22 February 2010 - 06:46 PM

Hello, Sashacat.

Thanks! I can credit most of the staff here for helping me learn. I joined the malware removal study program they offer. You learn a lot and end up being able to help others when you're done. I see you've been active on the forums...if you're interested in learning I can post a link to the signup to join the program. It's quite the commitment, so be warned. smile.gif

For this one, I just noticed you have Viewpoint installed. Please read below for info on that program. I also notice you're running Service Pack 2. You may want to consider installing SP3. Back up BEFORE you install SP3 if you choose to do so...you never know how these major upgrades are going to go. We'll do a Windows Update step below...you can skip SP3 now and install any other critical update, although I do recommend you update at some point. Go ahead and update your java. I included my standard speech on that below...dont' forget to uninstall the old versions first. It will also put in some automatic startup items, so feel free to remove them from startup if you want.

When you're done, please post one final DDS log. Is there anything else we need to do? If not I think we can uninstall our tools and start cleaning up our mess.





I see Viewpoint is installed on your machine. Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This changed from what we know in 2006 read this article:

http://www.clickz.com/news/article.php/3561546

I suggest you remove the program now. Go to the Control Panel, then Add or Remove Programs uninstall the following if they exist: Viewpoint, Viewpoint Manager, Viewpoint Media Player.



Step 1

Now, we need to update Windows.

It is important that you visit Windows Update regularly. This will ensure your computer has always the latest security updates available installed on your computer.

Please check now and if there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates. Please let me know when you have done this.



Step 2

Next, we need to update Java.
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 18 and save it to your desktop.
  • Scroll down to where it says "JDK 6 Update 18 (JDK or JRE)...allows end-users to run Java applications".
  • Click the "Download JRE" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) or Java™ in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.



Step 3

Please post one final DDS log. I notice that the services/drivers are all 'pending'...can you please wait a bit after a reboot? I'm not sure why the last couple of DDS logs show them as pending instead of actually running.

etavares


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#13 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 23 February 2010 - 03:33 PM

smile.gif
I would LOVE to have the opportunity to learn from the bleepingcomputer.com team!!!!

Glad you said that about Viewpoint, I've read about that, and it was in the back of my mind, just hadn't gotten up the nerve to do it yet.

I have no earthly idea about the DDS log, not familiar w/DDS, not experienced in DDS, so am glad you know about this smile.gif

Will do everything you advised and report back.

Thank you smile.gif
If we don't change the direction we are going,
We are likely to end up where we are headed.

#14 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 25 February 2010 - 09:34 PM

hello etavares,
aaargh!!!!!! Some days I don't love computers. Today is one of those days... sad.gif

I uninstalled Viewpoint Manager and Viewpoint Player.
Adobe Reader found/offered a new update so I installed that because it said it was a security update. Now I have the latest, 9.3.1.

Next I did Windows updates. Just like you said, I kept doing it until there were no more updates.
The first time there were 16 updates (stop laughing) smile.gif
One of the updates was a .Net Framework (think it was 3.5 ?) and after it went through the whole process,
it said installation of the .Net Framework failed.
Reboot was required , and the computer was fine (note the past tense).
The yellow shield appeared again. I did the next step in updates, and the computer was still fine.
The 3rd and final time it was the Windows XP SP3 update.
I figured I might as well install that too, to be safe.
Reboot was required after installation of XP SP3.
That's when it all went to poo.

Upon reboot, I got the error message,
"C:\Windows\system32\rundll32.exe (in the title bar of the error message)
Windows cannot access the specified device, path, or file.
You may not have the appropriate permissions to access the item."

I clicked "OK" to close it. Same message appeared again.
I wasn't too worried, because although it hasn't happened on my computer before, I'm familiar with the possibility of that type of error after having removed "bad things", that still have instructions to run a file on boot, that is no longer present.
The "cmd" prompt screen appeared, and THIS part is strange...the text in the cmd prompt dialog box was teeny tiny microscopic. I just put it down to the rundll32.exe that was no longer present.

Another change that occurred immediately after reboot of XP SP3 was that there were two extra files running on boot in Task Mngr (that were not previously running before XP SP3):
ctfmon
mscorsvw.exe

I ran Rkill just to be safe, and it found nothing to end process on.
Here's the Rkill log:

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Lisa Hill on 02/25/2010 at 14:12:40.

Processes terminated by Rkill or while it was running:

C:\Documents and Settings\Lisa Hill\Desktop\rkill.exe

Rkill completed on 02/25/2010 at 14:13:44.



Then I tried to update Malwarebytes' and got the "732 unable to update error".
Still wasn't too worried, because I'd read the post by quietman7:
For those having trouble running Malwarebytes Anti-Malware
that details the "732 unable to update error".
Figured the XP SP3 update did something strange, to suddenly give me the error on boot about the rundll32.exe (that I have NEVER HAD before now).
I opened Firefox to go get the instructions from that post, and got a "page cannot be displayed" error.
<heavy sigh>
Tried to open IE (I used to have IE6, and it used to work - again, note the past tense), no cigar.
One of the Windows updates was IE7.
When I try to run IE, it acts like it's going to open, then flashes open/closed really fast.
I still wasn't too worried, because I had updated Malwarebytes' late last night (02-24-10), and had database ver 3787.

I tried to update SUPERAntiSpyware, and it wouldn't update either.

I scanned with Malwarebytes', just to be sure.
Malwarebytes' scan came up clean, zero infections.
Here's the Malwarebytes' scan log:

Malwarebytes' Anti-Malware 1.44
Database version: 3787
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

2/25/2010 5:16:25 PM
mbam-log-2010-02-25 (17-16-25).txt

Scan type: Full Scan (C:\|)
Objects scanned: 187107
Time elapsed: 2 hour(s), 20 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

I disabled "ctfmon" in MSCONFIG again (had previously disabled it).
I'm reasonably certain the other new file running in Task Mngr "mscorsvw.exe" has to do with Microsoft .Net Framework.
What I DON'T know is why it would NOW be running on boot. It's not listed in MSCONFIG.

There was nothing I could do to make the internet work all afternoon. I waited until my son got home, and he used his iPod to access the internet and was able to look at the instructions for the "732 unable to update" error and read it to me.
Since I can't get IE to run (it just does that quick "flash open/closed"), I went to Control Panel, Internet Options, and sadly, there was no checkmark in "proxy" to remove. Ok, so that wasn't the problem. It would've been so much easier if that was the problem. Darn.

Then I noticed that my wireless icon in the tray area of the taskbar had a yellow triangle with a black exclamation mark, saying Signal Strength Excellent, Limited or No Connectivity.
I right clicked, hit "Repair" and it was unable to "repair". Went back to Control Panel, Network Connections, right clicked on Wireless Network Connection, hit Properties, clicked TCP/IP, hit Properties. There is a checkmark in "obtain IP Address Automatically". I thought maybe I could type it in manually, so I went to the cmd prompt, did an IPCONFIG. The top part has the proper info for IP Address (Ethernet Connection). The lower part (DNS) for some strange reason has 0.0.0.0.
I don't know how to make it work right. Needless to say I am distressed.

I plugged in the ethernet connection, HOPING Firefox would work. It works just fine.
IE still does not work, still opens/closes real quick.
I updated Malwarebytes' just fine, now have database ver 3794.

I didn't get to update Java, for dealing with all this, and thought I'd better wait to resolve these issues before proceeding further, in case I'm going to have to uninstall XP SP3 and/or the IE7 updates.

I have not done a System Restore, or uninstalled any updates, because I wanted to hear from you first, instead of doing stupid things and making matters worse.

Also, haven't done the DDS log yet, wasn't sure, kinda thought you wanted that after I got all of the updates (including the Java update).

Thanks.
If we don't change the direction we are going,
We are likely to end up where we are headed.

#15 Sashacat

Sashacat
  • Topic Starter

  • Members
  • 372 posts
  • OFFLINE
  •  
  • Local time:12:33 AM

Posted 25 February 2010 - 09:47 PM

Just ran DDS, here's the log:
(computer had been running SEVERAL HOURS before running DDS, as you requested earlier)



DDS (Ver_09-12-01.01) - NTFSx86
Run by Lisa Hill at 21:35:47.50 on Thu 02/25/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.191.60 [GMT -5:00]

AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.wftv.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [@OnlineArmor GUI] "c:\program files\tall emu\online armor\OAui.exe"
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\lisahi~1\applic~1\mozilla\firefox\profiles\gct4q43z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R? apusbsnt;Sierra Wireless USB Modem Device Driver
R? ECnvtBox;Embroidery Conversion Box Plus
R? NWUSBPort2;Novatel Wireless USB Status2 Port Driver
R? SASDIFSV;SASDIFSV
S? aswFsBlk;aswFsBlk
S? aswSP;aswSP
S? avast! Antivirus;avast! Antivirus
S? avast! Mail Scanner;avast! Mail Scanner
S? avast! Web Scanner;avast! Web Scanner
S? OAcat;Online Armor Helper Service
S? OADevice;OADriver
S? OAmon;OAmon
S? OAnet;OAnet
S? SASENUM;SASENUM
S? SASKUTIL;SASKUTIL
S? SvcOnlineArmor;Online Armor

=============== Created Last 30 ================

2010-02-25 17:42:51 0 d-----w- c:\windows\LastGood.Tmp
2010-02-25 17:23:32 0 d-----w- c:\windows\system32\scripting
2010-02-25 17:23:15 0 d-----w- c:\windows\l2schemas
2010-02-25 17:23:12 0 d-----w- c:\windows\system32\en
2010-02-25 17:23:11 0 d-----w- c:\windows\system32\bits
2010-02-25 16:23:22 0 d-----w- C:\36e20bafa888769343b3836564abcd
2010-02-25 15:33:38 52224 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-25 15:33:38 459264 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-02-25 15:33:37 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2010-02-25 15:33:36 268288 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-02-25 15:33:35 991232 ------w- c:\windows\system32\dllcache\ieframe.dll.mui
2010-02-25 15:33:34 6067200 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-02-25 15:33:33 63488 ------w- c:\windows\system32\dllcache\icardie.dll
2010-02-25 15:33:33 380928 ------w- c:\windows\system32\dllcache\ieapfltr.dll
2010-02-25 15:33:33 2452872 ------w- c:\windows\system32\dllcache\ieapfltr.dat
2010-02-25 14:48:34 16832 ----a-w- c:\windows\system32\amcompat.tlb
2010-02-25 14:48:33 23392 ----a-w- c:\windows\system32\nscompat.tlb
2010-02-25 14:30:58 0 d-----w- c:\program files\Windows Media Connect 2
2010-02-25 14:23:48 0 d-----w- c:\windows\system32\LogFiles
2010-02-21 16:56:26 0 d-----w- c:\docume~1\lisahi~1\applic~1\OnlineArmor
2010-02-21 16:56:26 0 d-----w- c:\docume~1\alluse~1\applic~1\OnlineArmor
2010-02-21 16:55:35 0 d-----w- c:\program files\Tall Emu
2010-02-21 16:36:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-02-19 02:38:43 0 d-----w- c:\program files\Process Explorer
2010-02-18 04:09:54 0 d-sha-r- C:\cmdcons
2010-02-18 04:05:55 77312 ----a-w- c:\windows\MBR.exe
2010-02-18 04:05:55 261632 ----a-w- c:\windows\PEV.exe
2010-02-18 04:05:55 161792 ----a-w- c:\windows\SWREG.exe
2010-02-18 04:05:54 98816 ----a-w- c:\windows\sed.exe
2010-02-11 19:29:07 0 d-----w- c:\windows\system32\Adobe
2010-02-09 20:04:13 0 d-----w- c:\program files\ESET
2010-02-05 18:23:49 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 14:37:46 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-02-01 14:37:45 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-02-01 14:37:25 223312 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-02-01 03:49:03 0 d-----w- c:\docume~1\lisahi~1\applic~1\Malwarebytes
2010-02-01 03:28:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-01 03:28:44 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-01 03:28:42 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-31 22:54:23 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:49:39 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-31 22:49:38 0 d-----w- c:\docume~1\lisahi~1\applic~1\SUPERAntiSpyware.com
2010-01-31 22:46:54 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-31 20:56:32 1744 ---ha-w- c:\windows\system32\dobijuzi
2010-01-31 20:35:10 0 d-----w- c:\docume~1\lisahi~1\applic~1\WinPatrol
2010-01-28 15:58:12 0 d-----w- c:\program files\ShowMyPC
2010-01-28 15:41:16 0 d-----w- c:\documents and settings\lisa hill\Tracing
2010-01-28 15:27:05 0 d-----w- c:\program files\Microsoft
2010-01-28 15:26:18 0 d-----w- c:\program files\Windows Live SkyDrive
2010-01-28 15:05:16 0 d-----w- c:\program files\common files\Windows Live
2010-01-27 12:57:57 0 d-----w- c:\program files\K9

==================== Find3M ====================

2010-01-30 23:24:07 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-27 19:13:56 30868 ----a-w- c:\windows\fonts\IllegalEdding.ttf
2010-01-27 19:13:08 100572 ----a-w- c:\windows\fonts\Degrassi.ttf
2010-01-27 19:12:36 53352 ----a-w- c:\windows\fonts\Searfont.ttf
2010-01-27 19:11:42 68352 ----a-w- c:\windows\fonts\Rufa.ttf
2010-01-24 21:36:31 166269 ----a-w- c:\windows\hpoins21.dat
2010-01-21 18:44:18 3472 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-19 18:38:28 66536 ----a-w- c:\windows\fonts\PressWriter_Symbols.ttf
2010-01-14 16:35:44 19573 ----a-w- c:\windows\hpqins13.dat
2010-01-13 08:31:43 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-01-13 08:31:21 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-13 03:36:09 69 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences2.dat
2010-01-13 03:36:09 39 ----a-w- c:\documents and settings\lisa hill\jagex_runescape_preferences.dat
2010-01-05 21:24:16 21704 ----a-w- c:\windows\system32\dopdfmn7.dll
2010-01-05 21:24:14 18632 ----a-w- c:\windows\system32\dopdfmi7.dll
2010-01-05 20:30:28 3599360 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 16:50:03 353792 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-31 15:33:06 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-18 13:05:43 634648 ------w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2009-12-16 18:43:27 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-16 18:43:27 343040 ------w- c:\windows\system32\dllcache\mspaint.exe
2009-12-14 07:08:23 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-14 07:08:23 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
2009-12-08 19:27:51 2189184 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 19:27:51 2189184 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-08 18:43:51 2023936 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-08 18:43:50 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 18:43:50 2066048 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-08 09:23:28 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll
2009-12-04 18:22:22 455424 ------w- c:\windows\system32\dllcache\mrxsmb.sys

============= FINISH: 21:40:22.51 ===============

Attached Files


If we don't change the direction we are going,
We are likely to end up where we are headed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users